Every number here came from a run.
Nothing below is a projection. Where a figure is approximate we say so, and where it comes from outside research we name who published it.
of benchmark vulnerability classes surfaced in one autonomous pass, each finding reproduced and scored before it was reported.
Memory is why the second figure exists. The same target, tested again, yields more because everything prior is retained rather than rediscovered.
verified findings, across more than twenty subdomains tested in parallel, with no human operator in the loop.
Roughly fifty times the output of a full boutique team over the same three days. A year of conventional testing, delivered over a long weekend, then repeated the following week.
The kinds of things it turns up.
Not theory. These are the classes of problem Cipher proves again and again across the estates it runs on, and the ones most likely to end up in a breach report.
Signing in as any account without ever knowing the password.
Live customer data sitting there for anyone who knows the address.
Change a number in a request and someone else's records come back.
Working credentials retrievable with no access to start from.
A version with a published exploit, still facing the internet.
Three issues nobody would have escalated, chained into a full takeover.
Faster than a consultancy. Deeper than a scanner.
Run it against your own estate.
One authorised target and a scope is enough to see this on your own estate.